Stored XSS Vulnerability in WHM Manage SSL Hosts Interface by cPanel
CVE-2026-93029

9CRITICAL

Key Information:

Vendor

Webpros

Vendor
CVE Published:
2 October 2026

What is CVE-2026-93029?

A stored XSS vulnerability exists within the WHM Manage SSL Hosts interface, which could enable attackers to execute arbitrary code. This flaw arises from insufficient input validation in user-supplied data, allowing malicious scripts to be stored and executed in the browser of an unsuspecting user. Successful exploitation poses significant risks as it may lead to unauthorized access to sensitive information or control over the affected system.

Affected Version(s)

cPanel 0 < 11.138.0.11

cPanel 0 < 11.136.0.45

cPanel 0 < 11.134.0.61

References

CVSS V3.0

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rz1027 (rz1027)
.